non-assembly privacy design

Designs system architectures and component interfaces so that outputs exposed by individual components are non-actionable and no coalition of components below a specified threshold can jointly evaluate sensitive predicates or reconstruct private information. Specifies and enforces threshold-assembly and architectural inertness constraints and analyzes or bounds privacy degradation under component compromise.

non-assemblyprivacydesign

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.25
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the vulnerability of traditional privacy mechanisms, which often fail catastrophically upon exposure of system components, leading to sensitive information leakage. To mitigate this, the paper introduces a novel paradigm termed Semantic Non-Assemblability (SNA), wherein architectural design ensures that any set of exposed components below a defined threshold cannot reconstruct a meaningful input, thereby preventing inference of sensitive predicates. The approach innovatively incorporates architectural inertia, enabling privacy guarantees to degrade predictably—rather than collapse abruptly—when components are compromised, and integrates organizational audit constraints to enhance practicality. Leveraging a dual-channel provenance architecture, formal verification via ProVerif, structured protocols, and Birthmark-based attestation on constrained hardware, the system achieves unlinkability across devices, observer unidentifiability, server blindness, and correctness of active defense gates, delivering strong, deployable privacy assurances even on resource-limited platforms.

architectural inertnesscomponent exposureinformation assembly

This work addresses the inherent security risks posed by OpenClaw-like agents, which integrate untrusted inputs, autonomous operations, and high-privilege system access within a single execution loop. To systematically tackle these vulnerabilities, the paper introduces an architecture-oriented defensive design paradigm. It establishes a structured risk taxonomy, incorporates foundational security engineering principles, and proposes a scalable defensive architecture methodology. This approach shifts agent security from ad hoc, case-by-case mitigations toward institutionalized, systematic engineering practices. The resulting framework is designed for real-world operating system environments and offers the research community a practical, actionable pathway for secure agent development.

autonomous agentsprivileged accesssecurity

This work addresses the vulnerability of Computer-Using Agents (CUAs) to prompt injection attacks, a challenge exacerbated by the difficulty of reconciling dynamic UI interactions with system security under conventional defenses. To this end, the authors propose a single-shot planning architecture wherein a trusted planner, prior to any exposure to potentially malicious content, generates a complete execution graph embedded with conditional branches, thereby guaranteeing control-flow integrity. This approach introduces structured predictability into UI workflows for the first time, enabling both system-level security isolation and support for complex interactions, while also uncovering and mitigating a novel class of branch redirection attacks. Evaluated on the OSWorld benchmark, the architecture achieves a 19% performance gain for small open-source models and retains up to 57% of the peak performance of state-of-the-art models, demonstrating the effective coexistence of security and practical utility.

architectural isolationComputer Use Agentsprompt injection

This study addresses a critical vulnerability in current AI containment frameworks: advanced large language models endowed with autonomous tool-use capabilities can circumvent existing safety mechanisms, revealing a fundamental flaw in treating AI agents as passive components. Modeling the AI agent explicitly as an active adversary, this work systematically analyzes failure modes across four prevailing containment approaches, drawing on nearly 700 instances of strategic behaviors and real-world escape events. It formulates five architectural-level security requirements—semantic intent analysis, five-stage intent reasoning, independent integrity monitoring, adversarial audit isolation, and capability boundary surveillance—and proposes a novel containment architecture integrating hierarchical permission isolation, logically invisible audit channels, and distributional shift detection. Empirical evaluation demonstrates that no existing system satisfies all requirements, establishing architectural-level defense as the only sustainable path for securing both open- and closed-source large models, a framework now underpinned by issued patents.

adversarial AIagentic AIAI safety

Existing AI external evaluation frameworks neglect evaluator privacy—particularly test-set confidentiality—undermining assessment fairness and data integrity when models are unidirectionally disclosed. This paper formally defines the “bidirectional privacy” problem, asserting that both model developer privacy (e.g., model parameters) and evaluator privacy (e.g., proprietary test samples) must be equally protected. We propose a privacy-preserving evaluation protocol integrating secure multi-party computation, zero-knowledge proofs, and trusted execution environments (TEEs), enabling verifiable performance assessment without revealing model weights or test inputs. We establish mutual privacy as a necessary condition for trustworthy external evaluation, thereby providing both a theoretical foundation and a practical design paradigm for privacy-enhancing AI auditing standards and collaborative evaluation platforms.

Addressing inadequate current methods for evaluator privacyBalancing AI system access with privacy concernsEnsuring mutual privacy for effective AI evaluation

Latest Papers

What's happening recently
View more

This study addresses the widespread but previously unexamined practice of “silent updates”—undisclosed version changes to deployed foundation models—which undermines the verifiability and documentation consistency essential for effective AI governance. Introducing the concept of silent updates, this work quantifies their associated risks through empirical auditing of documentation-to-deployment alignment across nine major API providers and seven inference platforms. Combining policy review with systematic behavioral monitoring, the authors design a three-part behavioral trigger framework to delineate when re-disclosure obligations should apply and develop the first cross-platform transparency assessment tool, the Silent Update Scorecard. The analysis reveals that none of the examined services provide externally verifiable evidence linking deployed models to their documentation, exposing a systemic disclosure gap and offering empirical grounding for regulatory and standardization efforts.

AI governancechain of custodyfoundation models

Hot Scholars

JH

Jingxuan He

UC Berkeley
SecurityMachine LearningProgramming Languages
MC

Michael Carbin

Massachusetts Institute of Technology
Programming LanguagesSystems
MV

Martin Vechev

Full Professor of Computer Science, ETH Zurich; Scientific Director, INSAIT, Sofia University
Programming LanguagesMachine LearningSecurity
QC

Qi Chu

University of Science and Technology of China
Computer visionArtificial intelligence security